I feel like Facebook screwed this up for everyone when people's feeds were covered with apps their friends were using. Now when a site asks you to authorize it with facebook, users don't feel like they can trust what it's going to do.
I feel like Facebook screwed this up for everyone when people's feeds were covered with apps their friends were using. Now when a site asks you to authorize it with facebook, users don't feel like they can trust what it's going to do.
Most app people are very happy to immediatly use the account email to send you stupid personalized followups, aka "Peter From Lame-App".
If it would be "click, see and forget" - OAuth signup would be great, but being required to accept spam really breaks the deal. I am not sure if too many people share that feeling, but it really bugs me.
The issue you point out with aggressive App spam on facebook is different with other services, I feel. Twitter Apps usually ask whether they might tweet something in my name. So I believe you are right, facebook might have screwed this up a little.
If you wish to track data that is connected to my identity, i.e. provide continuity in your service, store some stuff that I made, settings, preferences, you don't need my email address.
If you really wish to communicate: Talk to me on twitter, it's nearly public! With oauth you receive a token as a representation of my identity, not my email address. If you really need an email address - then why do you need oauth?
If I go to a store to just browse through the shelves I don't have to give the clerk my telefone number. Why would he need it anyway? To annoy me every once in a while and bully me into visiting his store, which I voluntarily entered in the first place?
Here is a positive example: - Go to iron.io - Log in with your twitter account - Nothing happens: You can use the app and they show you around pretty nicely.
Yet Iron provides a service upgrade, which requires credit information. They ask for it, specificly when they need it: When you want more from their service. In that case you have to provide them with the info.
This is how websites could handle this issue. Log in with oauth. If you REALLY personally need to contact me, then you can ask me later. Not upon login or to distinguish me from other people or provide continuity.
Emails are communication handles. They shouldn't be a poor man's surrogate database primary key.
I remain very curious: What does _your_ service need my email address for?
Regardless of how legitimate you think my usage of email addresses is the inability to even ask for it _is_ a downside. For those use cases that do require it immediately you now have a system where the user clicks the 'Login without filling in a form' button and gets thrown to a form anyway, which is exactly what we were trying to avoid.
Depending on how many users his service has, this could be a significant amount of work, even though the absolute probability of it happening is very low.
But do you have to do this whenever a completely new user tries to access the website? Is setting up an alternative access method not a very different concern?
So the only safe thing is abstinence. Don't type your FB password anywhere but when logging in directly to https://facebook.com
As you say, the whole point of OAuth is that you can safely use your FB account to log in to this other site. But -- to take this metaphor even further -- each time I encounter one of those things I always feel like a teenager being pressured into sex and being told "don't worry, this is safe, I promise, I love you." And I simply just don't know.
I'm confident I could recognize that www.facebook.com.scottba.io isn't Facebook, and I could probably train my parents on how to recognize that. But there has been extremely little user education on just what a "safe OAuth" site looks like. It's now putting an asterisk on all the old rules.
But I realize this kind of anti-phishing checking is beyond most users, and "Just don't enter your facebook password anywhere but when you are logging into facebook" probably IS a good heuristic for them.
I also don't know if some facebook oauth login paths use some kind of fancy ajax window-in-a-window so you _don't_ actually see facebook.com in your address bar -- which would make it pretty impossible for users to know if they're being phished or not.
This can never happen, because of the situation you highlighted. Most browsers do not let you do that anymore.
I went looking for sites using facebook logins and found this one just as the first unlucky example: http://www.nydailynews.com/login Once you know the browser and OS, it wouldn't be too hard to get something mostly like that pop-up into a div.
Even if they realize there is a consensual relationship going on between newsite.com & facebook, people don't know what's going on. Does this give newsite.com the ability to see my friends? Spam them? Does this give facebook access to my newsite.com stuff?
Is 'sign in with google" like that time linkedin had access my gmail and spammed everyone?
I think that's a grayer area than phising and something more people have actually been bitten by.
At this point, Facebook asks me to share my friends list (often much more) with site X: the only rational response is scrambling for the "close tab" button in the browser and writing off site X as untrustworthy jerks, because they dared to ask for unneeded personal information.
Now tell me again, how convenient is this global login that can at any time disappear from under your feet?
Also, whereas GMail is not inclined to police the morality of its users, FB is. Not the same as data-mining, not the same as "legality" - for example, you have repeatedly used a word that FB retroactively considers a bannable offense, say goodbye to your account; or you have, a long time ago, posted pictures that are considered indecent under the new rules; or enough other users maliciously coordinate to flag an innocuous item of yours - and the banhammer falls automatically.
Moreover, GMail != e-mail: you are completely free to register with any of the bazillion e-mail providers, there is no need to use GMail; as for Facebook, there is only one.
(in light of today's FB blackout)
So color me skeptical. It's good that I don't use Facebook or Twitter to log into your site. They successfully filter me out from the sort of site designed by people whose business needs are met better by social login. Yes, it's not you, it's me. I am only hindering your growth. So fly away freely. Come back only if our true love was meant to be.
Segmentation is a good thing, so long as it's recognized as segmentation.
But then Snowden dropped by to tell us that we can trust our own governments even less than all these companies.
What they don't make clear is that Facebook is informed every time people visit (or in some cases, login in to) those other sites and can generate better profiles from that data, even sleep schedules, even for people who rarely use FB itself.
I guess for me, the reason why signing up via Google is not as creepy feeling inducing as Facebook is because Google gives you the option of putting on Google+ whether or not you sign in to a given website. The default is still to put it in your feed, but at least you can choose not to put it in your feed.
If I have to sign in before I can see anything about it, I leave.
Getting users to do this though is part of my job and my job is often made easier either by auto-fill options in browsers and good form design.
URL based autho systems are pretty limited in their applications as anything on the other side would have to be of little importance. The security implications of such a system are massive...What if you need to log into an account and you use a work computer? Surely all someone needs to do is press ctrl-h(or access server logs) and visit the same url to gain access to your information.